Frank Olivo

Frank Olivo is the founder of Sagapixel. He writes on a number of topics related to digital marketing, but focuses mostly on SEO.

HIPAA-Compliant SEO: Is This Even Something to Worry About?

Category:
Table of Contents

I’ve been doing SEO for healthcare practices for over a decade, and I have some version of the same conversation almost every week. A practice owner tells me their website is HIPAA-compliant. Then I look under the hood and find Google Analytics 4 running out of the box, a Meta Pixel firing on every procedure page, and the whole site sitting on shared GoDaddy hosting.

They’re not lying to me — they genuinely believe they’re compliant, usually because their web designer told them the site “has an SSL” or their forms vendor has the word “secure” on its homepage. Meanwhile, the actual rules here don’t come from vague best practices. They come from a specific series of regulatory actions over the past few years, and once you understand what those actions actually said, HIPAA-compliant SEO stops being scary and starts being a checklist.

Here’s the thesis of this entire article: SEO itself almost never touches protected health information. The exposure lives in the tracking scripts, forms, hosting, and testimonials wrapped around your SEO — and every one of those problems has a known fix.how a view becomes PHI

What Is HIPAA-Compliant SEO?

HIPAA-compliant SEO means growing your organic visibility without collecting, exposing, or transmitting protected health information (PHI) through the tools surrounding that work.

Notice what’s not in that definition: rankings. Google doesn’t know or care whether your practice is a covered entity. There’s no “compliant” version of the algorithm, no special ranking rules for medical sites beyond the quality standards Google applies to all health content. Compliance governs what happens to visitor data — not which keywords you target or how you structure a service page.

Quick vocabulary, because it matters for everything below: a covered entity is a healthcare provider, health plan, or clearinghouse that handles PHI under HIPAA. A business associate is any vendor that touches PHI on a covered entity’s behalf — and business associates have to sign a Business Associate Agreement (BAA) accepting HIPAA obligations. Keep those three terms in mind; the entire question of “is this tool okay?” usually reduces to “does this vendor receive PHI, and if so, will they sign a BAA?”

How Tracking Pixels Became a Federal Issue

Most articles on this topic skip the actual history, which is a shame, because the history tells you exactly where the risk is.

2022 — The Markup investigation. Journalists found the Meta Pixel on the websites of 33 of the top 100 U.S. hospitals, sending data to Facebook when visitors did things like schedule appointments. Class-action lawsuits followed almost immediately.

December 2022 — the OCR bulletin. The HHS Office for Civil Rights responded with a bulletin declaring that tracking technologies on healthcare websites could create impermissible disclosures of PHI. The key move: OCR said an identifier as thin as an IP address, combined with a visit to a page about a specific condition or treatment, could itself constitute PHI. That put standard installs of Google Analytics and the Meta Pixel — neither of which is covered by a BAA — squarely in the crosshairs. In July 2023, OCR and the FTC jointly sent warning letters to roughly 130 hospital systems and telehealth providers.

March 2024 — OCR updates the bulletin. The revision clarified (somewhat) when tracked data counts as individually identifiable health information, but kept the core position intact.

June 2024 — American Hospital Association v. Becerra. A federal court in Texas ruled that OCR overreached. The court struck down the “proscribed combination” — the idea that IP-plus-page-visit on a public, unauthenticated page is automatically PHI. That narrowed the bulletin, but read the fine print: authenticated pages (patient portals, logged-in scheduling), intake forms, and anything where the visitor is identifiably a patient remain fully covered. The ruling was a scope correction, not a green light.

The FTC fills the gap. While OCR was fighting about covered entities, the FTC went after companies that aren’t covered entities at all. GoodRx paid $1.5 million in the first-ever enforcement of the Health Breach Notification Rule for sharing health data with advertisers. BetterHelp paid $7.8 million for similar conduct. If you’re a med spa or cash-pay practice telling yourself HIPAA doesn’t apply to you, the FTC would like a word.

State laws raise the floor. Washington’s My Health My Data Act — with private right of action — and copycat laws in Connecticut and Nevada now regulate consumer health data far beyond HIPAA’s reach.

So here’s where the law actually stands in 2026: the most aggressive version of OCR’s position was trimmed for public pages, but the combination of remaining OCR guidance, FTC enforcement, state privacy laws, and an active class-action bar means the practical answer hasn’t changed. Sending identifiable visitor data plus health context to Google or Meta without safeguards is a liability, and neither company will sign a BAA for its standard ad and analytics products.

The SEO Work That Carries Zero Risk

This is the part that should lower your blood pressure. Almost everything that actually moves rankings involves editing a website, not collecting patient data:

  • Keyword research
  • Writing condition pages, procedure pages, and blog content
  • On-page optimization, internal linking, title tags
  • Technical SEO — site speed, crawlability, schema markup
  • Google Business Profile optimization and local citations

None of that touches a patient. In fact, the highest-ROI work in healthcare SEO — building out educational content for the conditions you treat — is the safest thing you can possibly do, because it’s written for a general audience and never references a real person.

Where Healthcare Websites Actually Get Exposed

where the hipaa risk exists

Analytics and ad pixels

A pageview on /breast-augmentation means nothing on its own. A pageview on /breast-augmentation tied to an IP address, a click ID, or a logged-in user is a statement that an identifiable person is seeking specific care — and when your stock GA4 or Meta Pixel install ships that to Google or Meta, you’ve disclosed it to a vendor with no BAA. This is the single most common problem I find on healthcare websites, and it’s usually there because a generalist marketer set the site up exactly the way they’d set up an e-commerce store.

Your hosting

Here’s the exposure almost nobody talks about: even if your forms are compliant and your analytics are scrubbed, your hosting company sits underneath everything. Server logs capture every visitor’s IP address alongside every URL they load — the same identifier-plus-health-context combination that started this whole mess — and if your host stores your form submissions in its database, it’s holding PHI outright.

The worst case I’ve personally seen was an addiction treatment center whose SEO we took over. The site was on shared GoDaddy hosting, and the contact form had been quietly storing the submissions of every person who had ever asked about treatment — names, contact info, and the fact that they were seeking help for addiction, which is among the most sensitive health information that exists (addiction records carry extra federal protection under 42 CFR Part 2). And the site had been hacked. It was actively injecting links to a Turkish adult-content website while a database full of prospective patients’ information sat on a commodity server with no BAA in sight. That’s not a hypothetical risk profile. That’s a breach-notification event waiting for someone to notice.

If patients visit your site, your host holds data about them. You need either a hosting provider that will sign a BAA or an architecture that keeps identifiable data out of the host’s hands.

Contact and intake forms

The “describe your symptoms” box is a PHI generator. Where does it go? If the answer is a front-desk email inbox or a CRM nobody vetted, you have a problem regardless of how the form looks to the visitor.

Chat widgets and call tracking

A chat transcript describing someone’s condition, or a recorded call to a tracked number, is PHI the moment it’s tied to an identifiable person. Both are fixable — with the right vendors under BAA — but neither is fine by default.

Testimonials, reviews, and before/after photos

Publishing a patient story or photo requires signed, specific written authorization. And the trap that catches even careful practices: review responses. Replying “Thank you for trusting us with your tummy tuck, Maria!” confirms both that Maria is a patient and what she had done, in a permanently public, indexed comment. Thank reviewers warmly and generically. Never confirm a treatment relationship.

The Fix: Server-Side Tagging

server-side tagging explained

Ripping out all analytics — which is what a lot of practices did in a panic after 2022 — is the wrong answer. Flying blind on which campaigns and pages produce patients is how marketing budgets get wasted. The right answer is changing the architecture so measurement continues without PHI ever reaching Google or Meta.

How it works: instead of the visitor’s browser sending data directly to Google and Meta, events route through a server-side tagging container that you control. That intermediary strips identifiers and health context — IP addresses, sensitive URL paths, form contents — before anything is forwarded. Google Analytics still gets aggregate behavioral data it can use; Meta’s Conversions API still gets the conversion signals your ad campaigns need to optimize; neither gets PHI.

What it costs: this is where I’ll be blunt about the market. Health systems with deep pockets solve this with platforms like Freshpaint, which are excellent — and run into the tens of thousands of dollars per year. That’s simply not realistic for an independent practice. At Sagapixel we’ve built the same architecture on infrastructure that costs most of our clients a little over $500/month, with a one-time setup fee, and the client owns the account outright. The point isn’t my offer specifically — it’s that compliant conversion tracking is now a few-hundred-dollars-a-month problem, not an enterprise project, and any practice can afford to stop choosing between measurement and compliance.

When you need a BAA, and from whom: any vendor that receives PHI — hosting, forms, chat, call tracking, the tracking intermediary. One nuance the ranking articles get fuzzy: an SEO agency doing pure content and technical work, with no access to form submissions or patient data, generally doesn’t need a BAA. The moment the agency touches your CRM, your form backend, or identifiable tracking data, it does.

How to Vet an SEO Agency for HIPAA Awareness

Ask these before signing anything:

  1. Where do my form submissions go, and who can access them?
  2. What’s your tracking architecture — and specifically, does any identifiable data reach Google or Meta directly?
  3. Will you sign a BAA if your work touches PHI?
  4. Have you handled the review-response and testimonial-authorization side for other healthcare clients?

The red flag that ends the conversation for me: an agency that ships default GA4 and a Meta Pixel on a healthcare website in 2026. It tells you they’ve never read the bulletin, never followed the litigation, and are treating your practice like an online store.

HIPAA SEO Compliance Checklist

  • Audit every form — what it collects, where it lands, who sees it
  • Inventory every script — know exactly what fires on condition and procedure pages
  • Check your hosting — BAA in place, or identifiable data kept out of server logs and databases
  • Verify authorizations — a signed release on file for every testimonial and photo
  • Standardize review responses — one neutral template, everyone uses it
  • Confirm BAAs — with every vendor that touches PHI
  • Move conversion tracking server-side — keep the measurement, drop the exposure

FAQ

Is Google Analytics HIPAA compliant?
Not by default, and Google won’t sign a BAA for it. It can be used compliantly only behind a server-side setup that strips identifiers and health context before data reaches Google.

Can SEO itself violate HIPAA?
The core work — keyword research, content, technical optimization — can’t, because it never touches patient data. Violations come from the tracking, forms, hosting, and testimonial layer around it.

I run a med spa / cash-pay practice. Does any of this apply to me?
Yes. Even where HIPAA doesn’t reach, the FTC’s Health Breach Notification Rule and state laws like Washington’s My Health My Data Act do — and the FTC has already collected millions from companies that shared health data with ad platforms.

Does my SEO agency need to sign a BAA?
Only if they access PHI — form submissions, patient lists, identifiable tracking data. Content-and-technical-only engagements generally don’t require one.

Didn’t the 2024 court ruling make tracking pixels legal again?
No. It narrowed OCR’s position on public, unauthenticated pages. Authenticated pages, forms, and anything tying an identifiable person to health information remain covered — and FTC enforcement, state laws, and class actions never went away.

The Bottom Line

Compliance and rankings are not in tension. The practices that fix the data layer once — hosting, forms, server-side tracking, testimonial process — get to run aggressive, full-throttle SEO with none of the exposure, while their competitors either fly blind or quietly leak patient data to ad platforms. This article is educational, not legal advice; run your specific situation past qualified counsel.

If you want a second set of eyes on your site’s tracking, forms, and hosting setup — or you want compliant conversion tracking stood up without the enterprise price tag — that’s exactly what we do at Sagapixel for healthcare practices every day.

Schedule a call with us